LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-14-2003, 01:09 AM   #1
thetwin
Member
 
Registered: Feb 2003
Distribution: Linux RedHat 7.2
Posts: 47

Rep: Reputation: 15
Openssh question


Greetings

I am running Redhat 7.2 and when I look at the Redhat errata site for updates to openssh, the most current for my distribution is openssh-3.1p1-6.i386.rpm.........However when I check rpmfind, I find openssh-3.5p1-1.i386.rpm from a place called Stuff on Rufus.W3.Org...My question is... it okay to install this rpm to update openssh or will that cause problems?

Cheers
 
Old 03-14-2003, 03:53 AM   #2
fmotta
LQ Newbie
 
Registered: Mar 2003
Posts: 10

Rep: Reputation: 0
Genreally - there are dependencies which could complain upon install and upon upgrade - the packages commonly check dependencies (like openssl in this case) - if you force the install (see rpm man page) then you may not have problems - for now - later you may have to force other packages - I generally install from sources even on redhat - then I can upgrade as I feel I need.
 
Old 03-14-2003, 01:25 PM   #3
thetwin
Member
 
Registered: Feb 2003
Distribution: Linux RedHat 7.2
Posts: 47

Original Poster
Rep: Reputation: 15
Thanks,

I guess I will look at installing from source. Being new it is easier to install/upgrade from RPM...
 
Old 03-14-2003, 02:00 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
DONT

OpenSSH >= 3.3 contain remotely exploitable vulnerabilities.
Use 3.4 or 3.5 and be sure you also check your OpenSSL usage.

In general before asking upgrade questions check the maintainers/developers site for security reports, then the vendors site.
Then decide.
 
Old 03-15-2003, 12:04 PM   #5
thetwin
Member
 
Registered: Feb 2003
Distribution: Linux RedHat 7.2
Posts: 47

Original Poster
Rep: Reputation: 15
I think I didn't ask the question properly. My concern was not the
upgrade itself, but the rpm coming from a place other than RedHat. I was unsure if this rpm would install properly or not. I had only used Redhat errata site previously to installing this rpm.

Thanks..upgrade went well.

Cheers
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenSSH question? JeRrYmAn Linux - General 18 11-21-2003 02:52 AM
OpenSSH, patch question sopiaz57 Linux - Security 1 11-05-2003 09:26 PM
OpenSSH gregoryfrancis Linux - General 4 03-02-2003 01:09 PM
Another Openssh question Crusufix Linux - Newbie 1 12-07-2001 02:12 PM
OpenSSH Tarantismic Yak Linux - Security 2 07-14-2001 04:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration